> Markdown version of [/jobs/ext/2572895-information-security-analyst-sr-principal-cloud-hybrid](https://www.wearedevelopers.com/jobs/ext/2572895-information-security-analyst-sr-principal-cloud-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst Sr Principal - Cloud - Hybrid - **Company:** General Dynamics View all jobs - **Location:** Fort Meade, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $142,792.0 - $184,000.0 - **Contract:** Permanent contract - **Skills:** Access Control List, Agile Methodology, Software System Penetration Testing, User Authentication, Microsoft Azure, Backup Devices, Cloud Computing, Cyber Security, Network Address Translation, Disaster Recovery, Identity and Access Management, Systems Analysis, Networking Hardware, Subnetting, Key Management, McAfee VirusScan, Security Software, Software Vulnerability Management, C4i, HybridCloud, Firewalls (Computer Science), Information Technology, Nessus, Api Gateway - **Published:** August 31, 2026 - **Apply:** https://www.careerjet.com/job/us8607915f6f1eb66fe8983edb951a2f40/eaa ## About the Role Skills: Cybersecurity, Information Security, RMF, Security Requirements, System Security Certifications: None Experience: 8 + years of related experience, * Active DoD Security Clearance of SECRET, or higher * Minimum eight (8) + years' experience and proven track record supporting IT customers as part of an enterprise environment. * BA/BS and 8+ years of Computer Science or equivalent experience * CISSP, CASP, CISA, CISM or similar for IAM Level III DoD 8570/8140 certification * Experience with FedRAMP Cloud processes * Knowledge of the DoD cybersecurity and policy requirements set forth in DoDI 8500.01 "Cybersecurity", NIST 800-53v5 Assessing Privacy and Security Controls and DoDI 8510.01 "Risk Management Framework * Extensive and experience in NIST 800-53, Risk Framework security controls in eMASS * Ability to lead in highly collaborative, fast-paced, growth-focused environment. * Experience and knowledge in cybersecurity tools such as Nessus ACAS, Microsoft Defender Endpoint, McAfee * Extensive experience and knowledge with Incident Response testing/plans and Contingency testing/plans * Experience with systems that deploy API gateways, firewalls, access control lists, IP subnetting, NAT and other network device in Cloud. * Experience communicating with and coordinating across multiple stakeholders and teams to align to and execute unified goals and plans. * The ability to effectively communicate with people ranging from non-technical to engineering level. Desired Qualifications: * Familiarization with DoD enterprise environments * Familiarization with Agile work environments * Familiarization with Microsoft Azure Cloud environment ## Description As an Information Security Analyst Sr Principal, you will be responsible for the ICAM program's network accreditation on both unclassified and classified networks. You will also be responsible for executing and reviewing security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations, and recommend mitigation strategies. In this role, a typical day will include: * Execute success in obtaining an accreditation and maintaining the accreditation for ICAM on a classified network. * Perform Risk Management Framework (RMF) actions in eMASS such as control assessments, PPSM, upload and manage ICAM assets in hardware/software list, upload STIG checklists and ACAS vulnerability reports. * Define, draft, publish, and maintain Information Security policies, standards, and guidelines such as Access Control Plan, Identification and Authentication Plan, Auditing and Accountability Plan, Contingency Plan, Incident Response Plan, Vulnerability Management, Continuous Monitoring, Backup and Recovery, System Integrity Plan, Key Management, Media Protection, etc. * Develop and finalize RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports * Assess system compliance against NIST, DoD, and DHA security requirements to include the NIST 800-53 controls, and DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs). * Spearhead support government compliance assessments such as penetration testing and accreditation and compliance inspections assessments and mitigations to system security threats/risks throughout the program life cycle. * Work with the internal and external stakeholders to resolve compliance or audit issues in a timely manner. Enforce the design and implementation of trusted relations among external systems and architectures. * Ensure system security needs are established and maintained for operations development, security requirements definition, security risk assessment, systems analysis, systems design, security test and evaluation, certification and accreditation, systems hardening, vulnerability, testing and scanning, incident response, disaster recovery, and business continuity planning; and provides analytical support for security policy development and analysis. * Other related work as directed., As a C4I analyst, you use your specialized functional experience and attention to detail to conduct all-source analysis with an emphasis on national C4I analysis in compliance with… + 24 days ago + Apply easily + ## Related Videos - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)